exam questions

Exam 500-220 All Questions

View all questions & answers for the 500-220 exam

Exam 500-220 topic 3 question 23 discussion

Actual exam question from Cisco's 500-220
Question #: 4
Topic #: 3
[All 500-220 Questions]


Refer to the exhibit. What is an advantage of implementing inter-VLAN routing on an MX Security Appliance rather than performing inter-VLAN routing on an MS Series Switch?

  • A. The MX appliance performs IDS/IPS for inter-VLAN traffic.
  • B. The MX appliance performs AMP for inter-VLAN traffic.
  • C. The MX appliance performs data encryption for inter-VLAN traffic.
  • D. The MX appliance performs content filtering for inter-VLAN traffic.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DRHoppo
Highly Voted 1 year, 12 months ago
Answer A: Intrusion Detection and Prevention Intrusion detection feeds all packets flowing between the LAN and internet interfaces, and in between VLANs through the SNORT® intrusion detection engine, and logs the generated alerts to the Security Report. You can export these alerts via Syslog. referance: https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Threat_Protection
upvoted 10 times
...
WickedShammy
Most Recent 8 months ago
A is the correct answer. From this: https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Threat_Protection#Intrusion_Detection_and_Prevention Intrusion Detection and Prevention In both IDS and IPS modes the following is inspected: all traffic between LAN and Internet (this is both modes, IPS/IDS) all traffic between VLANS (this is both modes, IPS/IDS) In both IDS and IPS modes the following is not inspected: INTRA-VLAN traffic (where Client 1 and Client 2 are both in the same VLAN)
upvoted 1 times
...
rnunes1110
11 months ago
Selected Answer: A
Correct: A
upvoted 1 times
...
CaptainPirate
1 year, 2 months ago
A IS THE CORRECT ANSWER
upvoted 1 times
...
18HandsOfLohan
1 year, 8 months ago
Selected Answer: A
Answer A (as only IDS/IPS applies to inter-vlan routing, AMP 'only' inspects HTTP traffic)
upvoted 2 times
...
NetworkGuy101
1 year, 8 months ago
Selected Answer: A
If you’re passing traffic between VLANs then the MX firewalls apply as well as the IDS/IPS rules, but not the AMP - that only applies to traffic arriving directly on the WAN/internet port.
upvoted 2 times
...
donAdriano
1 year, 10 months ago
Pros: You can offload routing tasks from the Cisco Meraki MX security appliance. Inter-VLAN traffic uses less hops. Cons: Inter-VLAN traffic does not reach the Cisco Meraki MX security appliance, so the appliance cannot filter this traffic. Correct answer: A With this design option, the security features of the Cisco Meraki MX security appliance, such as IDS and IPS, are not used for inter-VLAN traffic.
upvoted 2 times
...
Netmanb2k
1 year, 10 months ago
@DRHoppo MX LAN traffic across subnets (inter-VLAN) goes through Firewall, AMP, and IPS. • IPS is unlikely to trigger since most of the signatures are designed for Inbound Services • AMP is unlikely to see much inter-VLAN traffic because it is only checking HTTP traffic and most malware files moving across a LAN are not going over HTTP.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago